ZeroHour

CVE-2022-2131

CVSS 3.1
9.8 critical
EPSS
<1%p56
Published
()
Modified
Description

OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack.

Vendors
openkm
Products
openkm
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.